Cutwail
- First seen
- 2007-12-01 00:00:00
- Malware type
- botnet, ddos
- Family
- Malware family
- Last IoC activity
- 2026-07-12 06:29:16
- Profile updated
- 2026-07-07 12:40:38
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
Cutwail is a notorious botnet primarily used for sending spam emails and conducting DDoS attacks. It has been one of the largest and longest-running spam botnets, often utilized in combination with other malware to distribute malicious payloads.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Cutwail_Auto (yara-rule)
Related threat objects
- Cutwail (infrastructure)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- secureworks.com — Gold Essex (report)
- CrowdStrike — Report2021Gtr (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
- shadowserver.org — Has The Sun Set On The Necurs Botnet (report)
- web.archive.org — Blackhat Eu 2010 Carrera Silberman State Of Malware Slides (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cutwail (report)
- secureworks.com — Gold Essex (report)
- McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
- mimecast.com — How To Slam A Door On The Cutwail Botnet Enforce Dmarc (report)
- github.com — 2020 09 07 Dridex Iocs.Txt (report)
- McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
- securityintelligence.com — Dridex Campaign Propelled By Cutwail Botnet And Powershell (report)
- darknetdiaries.com — 110 (report)
- jsac.jpcert.or.jp — Jsac2020 5 Sajo Takeda Niwa En (report)